⤷ Title: Subscription Bypass Leading to Full Access to Paid Features
════════════════════════
𐀪 Author: Hossam Hamada
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:14:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #writing_tips #business_logic #bugbounty_writeup
════════════════════════
𐀪 Author: Hossam Hamada
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:14:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #writing_tips #business_logic #bugbounty_writeup
Medium
Subscription Bypass Leading to Full Access to Paid Features
Hi, my name is Hossam Hamada, I’m a Bug Bounty Hunter, and today I’ll be sharing a vulnerability I discovered in a Bug Bounty program on…
⤷ Title: Thoughts about email verification process in web applications
════════════════════════
𐀪 Author: Wsxcxx
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:53:21 GMT
════════════════════════
⌗ Tags: #sign_up #programming #application_security #application_development #email_verification
════════════════════════
𐀪 Author: Wsxcxx
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:53:21 GMT
════════════════════════
⌗ Tags: #sign_up #programming #application_security #application_development #email_verification
Medium
Thoughts about email verification process in web applications
I tried to talk about the title without code or drawing in this article. I thought this is be quite nice and fine topic to talk about.
⤷ Title: TryHackMe: Year of the Owl Writeup
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:20:38 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #information_security #tryhackme
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:20:38 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #information_security #tryhackme
Medium
TryHackMe: Year of the Owl Writeup
This box is ranked hard difficulty on THM, it involves heaps of enumeration on both TCP/UDP, exploiting WINRM to get a foothold on the…
⤷ Title: The Patch Hunter: Automating 1-Day Exploits with DiffRays and IDA Pro
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 03:06:01 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AutoDiff #Binary Diffing #CVE #DiffRays #Exploit Development #IDA Domain API #IDA Pro #Patch Analysis #reverse engineering #Vulnerability Research #Winbindex
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 03:06:01 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AutoDiff #Binary Diffing #CVE #DiffRays #Exploit Development #IDA Domain API #IDA Pro #Patch Analysis #reverse engineering #Vulnerability Research #Winbindex
Information Security News
The Patch Hunter: Automating 1-Day Exploits with DiffRays and IDA Pro
DiffRays is a research-oriented tool for binary patch diffing, designed to aid in vulnerability research, exploit development, and reverse engineering. It leverages IDA Pro and the IDA Domain API …
⤷ Title: Unlocking the Speed of Light: How Hardware-Accelerated BitLocker Saves Your FPS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:59:14 +0000
════════════════════════
⌗ Tags: #Windows #BitLocker #CPU Offloading #Encryption #Intel Panther Lake #Microsoft Ignite 2025 #NVMe #SSD performance #Windows 11 #Windows Security #XTS_AES_256
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:59:14 +0000
════════════════════════
⌗ Tags: #Windows #BitLocker #CPU Offloading #Encryption #Intel Panther Lake #Microsoft Ignite 2025 #NVMe #SSD performance #Windows 11 #Windows Security #XTS_AES_256
Information Security News
Unlocking the Speed of Light: How Hardware-Accelerated BitLocker Saves Your FPS
Microsoft has introduced a new hardware-accelerated version of its built-in BitLocker encryption in Windows 11. The feature is designed to boost performance and reduce CPU load by offloading heavy…
⤷ Title: The Robot Revolter: How Hackers Turned a $14,000 Humanoid Into a Physical Attacker
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:57:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI safety #cybersecurity #DARKNAVY #GEEKCon 2025 #Humanoid Robots #IoT Security #Physical Botnet #Robot Hacking #Unitree G1 #Unitree Go2 #Voice Command Exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:57:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI safety #cybersecurity #DARKNAVY #GEEKCon 2025 #Humanoid Robots #IoT Security #Physical Botnet #Robot Hacking #Unitree G1 #Unitree Go2 #Voice Command Exploit
Information Security News
The Robot Revolter: How Hackers Turned a $14,000 Humanoid Into a Physical Attacker
Commercial robots have proved far less secure than many assume. Security researchers are increasingly demonstrating that certain machines can be taken over in a matter of minutes, and that flaws i…
⤷ Title: The Dark Side of Telegram: Inside the $2B/Month Crypto Laundering Bazaars
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:56:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Fraud #Dark Web #Elliptic #Huione Guarantee #Money Laundering #pig butchering #Southeast Asia #Telegram #Tether #Tudou Guarantee #USDT #Xinbi Guarantee
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:56:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Fraud #Dark Web #Elliptic #Huione Guarantee #Money Laundering #pig butchering #Southeast Asia #Telegram #Tether #Tudou Guarantee #USDT #Xinbi Guarantee
Information Security News
The Dark Side of Telegram: Inside the $2B/Month Crypto Laundering Bazaars
The world’s largest online black markets may no longer reside in the dark web, but openly on Telegram itself. According to analysts, a sprawling network of Chinese-language “guarantor markets” has…
⤷ Title: Emergency Patch: Microsoft Issues Out-of-Band Fix for Broken MSMQ Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:54:51 +0000
════════════════════════
⌗ Tags: #Windows #bug fix #Enterprise IT #IIS #KB5074976 #Microsoft #MSMQ #Out_of_Band #Patch Tuesday #Sysadmin #Windows Server #Windows Update
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:54:51 +0000
════════════════════════
⌗ Tags: #Windows #bug fix #Enterprise IT #IIS #KB5074976 #Microsoft #MSMQ #Out_of_Band #Patch Tuesday #Sysadmin #Windows Server #Windows Update
Information Security News
Emergency Patch: Microsoft Issues Out-of-Band Fix for Broken MSMQ Infrastructure
Microsoft has released an out-of-band update to address a Message Queuing issue that emerged after the December 2025 update. The newly issued patches apply to Windows 10 22H2 ESU, Windows 10 Enter…
⤷ Title: The AMX Lockdown: Critical KVM Bug Allows Guest VMs to Crash Linux Hosts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 03:11:17 +0000
════════════════════════
⌗ Tags: #Linux #Cloud Security #dos #FPU #Hypervisor #Intel AMX #kernel panic #KVM #Linux Kernel #Paolo Bonzini #red hat #virtualization #Xeon Scalable #XSAVE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 03:11:17 +0000
════════════════════════
⌗ Tags: #Linux #Cloud Security #dos #FPU #Hypervisor #Intel AMX #kernel panic #KVM #Linux Kernel #Paolo Bonzini #red hat #virtualization #Xeon Scalable #XSAVE
Daily CyberSecurity
The AMX Lockdown: Critical KVM Bug Allows Guest VMs to Crash Linux Hosts
An unpleasant flaw surfaced in Linux—one capable of causing serious headaches for server administrators, particularly in public cloud environments. The issue arises when a KVM guest virtual machin…
⤷ Title: Beyond Pixel: Google Rebrands Magic Cue to Bring Proactive AI to All Androids
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:30:54 +0000
════════════════════════
⌗ Tags: #Android #AI #android #Contextual Suggestions #Gemini Nano #google #Google Play Services #machine_learning #Magic Cue #Pixel 10 #privacy #Private Compute Core
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:30:54 +0000
════════════════════════
⌗ Tags: #Android #AI #android #Contextual Suggestions #Gemini Nano #google #Google Play Services #machine_learning #Magic Cue #Pixel 10 #privacy #Private Compute Core
Daily CyberSecurity
Beyond Pixel: Google Rebrands Magic Cue to Bring Proactive AI to All Androids
Earlier this year, Google introduced the Pixel 10 lineup with a headline AI feature called “Magic Cue,” designed to proactively offer services based on a user’s context. That capability now appear…
⤷ Title: The 2nm Overflow: Why AMD and Tesla are Deserting TSMC for Samsung’s Texas Fab
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:24:50 +0000
════════════════════════
⌗ Tags: #Technology #18A #2nm #AMD #Apple #Digital Markets Act #Foundry #GAA #geopolitics #google #intel #nvidia #samsung #Taylor Texas #Tesla #TSMC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:24:50 +0000
════════════════════════
⌗ Tags: #Technology #18A #2nm #AMD #Apple #Digital Markets Act #Foundry #GAA #geopolitics #google #intel #nvidia #samsung #Taylor Texas #Tesla #TSMC
Daily CyberSecurity
The 2nm Overflow: Why AMD and Tesla are Deserting TSMC for Samsung’s Texas Fab
Although TSMC continues to sit unchallenged at the pinnacle of process technology—commanding an effective 100% share of advanced AI chip manufacturing—two powerful forces, capacity constraints and…
⤷ Title: Intel’s 14A/18A Super Chip: The AI “System Foundry” That Challenges TSMC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:19:24 +0000
════════════════════════
⌗ Tags: #Technology #14A #18A_PT #AI Silicon #EMIB_T #Foveros Direct 3D #HBM4 #HBM5 #Heterogeneous Integration #Intel Foundry #PowerDirect #RibbonFET 2 #TSMC CoWoS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:19:24 +0000
════════════════════════
⌗ Tags: #Technology #14A #18A_PT #AI Silicon #EMIB_T #Foveros Direct 3D #HBM4 #HBM5 #Heterogeneous Integration #Intel Foundry #PowerDirect #RibbonFET 2 #TSMC CoWoS
Daily CyberSecurity
Intel’s 14A/18A Super Chip: The AI “System Foundry” That Challenges TSMC
In a bid to demonstrate that it can truly rival TSMC in the foundry arena, Intel recently released a conceptual technology video through Intel Foundry, unveiling its next-generation hybrid packagi…
⤷ Title: The End of AirPods’ Monopoly: Apple to Unlock Proximity Pairing and Smartwatch Replies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:01:03 +0000
════════════════════════
⌗ Tags: #Technology #AirPods #Apple #Apple Watch #Bluetooth #DMA #European Union #iOS 26.3 #iphone #Proximity Pairing #sony #Tech Policy 2026 #Wear OS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:01:03 +0000
════════════════════════
⌗ Tags: #Technology #AirPods #Apple #Apple Watch #Bluetooth #DMA #European Union #iOS 26.3 #iphone #Proximity Pairing #sony #Tech Policy 2026 #Wear OS
Daily CyberSecurity
The End of AirPods’ Monopoly: Apple to Unlock Proximity Pairing and Smartwatch Replies
To comply with the European Union’s stringent Digital Markets Act (DMA), Apple is expected to introduce two pivotal features for the EU in the upcoming iOS 26.3 update: third-party device Proximit…
⤷ Title: Hackers Revive 2020 FortiGate Flaw to Bypass 2FA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:53:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #active directory #CVE_2020_12812 #cyber attack #firewall security #FortiGate #Fortinet #LDAP #network_security #Patch Alert #SSL VPN
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:53:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #active directory #CVE_2020_12812 #cyber attack #firewall security #FortiGate #Fortinet #LDAP #network_security #Patch Alert #SSL VPN
Daily CyberSecurity
Hackers Revive 2020 FortiGate Flaw to Bypass 2FA
Fortinet has issued a warning regarding the active exploitation of a three-year-old vulnerability that allows attackers to bypass two-factor authentication (2FA) on FortiGate firewalls simply by c…
⤷ Title: “LotusBail” Trap: 56,000 Developers Downloaded a Fake WhatsApp API That Works perfectly—While Stealing Everything
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:41:07 +0000
════════════════════════
⌗ Tags: #Malware #@whiskeysockets/baileys #backdoor #data exfiltration #JavaScript Security #KOI Security #lotusbail #malware #npm #Open Source Security #supply chain attack #WhatsApp API
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:41:07 +0000
════════════════════════
⌗ Tags: #Malware #@whiskeysockets/baileys #backdoor #data exfiltration #JavaScript Security #KOI Security #lotusbail #malware #npm #Open Source Security #supply chain attack #WhatsApp API
Daily CyberSecurity
“LotusBail” Trap: 56,000 Developers Downloaded a Fake WhatsApp API That Works perfectly—While Stealing Everything
A new investigation by Koi Security has exposed a highly sophisticated supply chain attack lurking in the npm registry. For six months, a package named lotusbail masqueraded as a legitimate WhatsA…
⤷ Title: Evasive Panda APT Hijacks Dictionary.com and App Updates in Two-Year Spree
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:37:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #cyber_espionage #Daggerfly #DLL Sideloading #DNS Poisoning #Evasive Panda #Kaspersky Labs #malware #MgBot #Software Update Hijack #SohuVA #StormBamboo
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:37:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #cyber_espionage #Daggerfly #DLL Sideloading #DNS Poisoning #Evasive Panda #Kaspersky Labs #malware #MgBot #Software Update Hijack #SohuVA #StormBamboo
Daily CyberSecurity
Evasive Panda APT Hijacks Dictionary.com and App Updates in Two-Year Spree
A notorious cyber-espionage group has spent the last two years conducting a highly targeted surveillance campaign, hijacking network traffic and poisoning DNS responses to deliver malware through …
⤷ Title: High-Severity Flaws in TeamViewer DEX Allow Attackers to Hijack Nomad Services
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:33:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #1E #Code Execution #Command Injection #CVE_2025_44016 #DEX #Digital Employee Experience #Nomad Branch #Patch Tuesday #privilege escalation #TeamViewer #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:33:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #1E #Code Execution #Command Injection #CVE_2025_44016 #DEX #Digital Employee Experience #Nomad Branch #Patch Tuesday #privilege escalation #TeamViewer #Windows Security
Daily CyberSecurity
High-Severity Flaws in TeamViewer DEX Allow Attackers to Hijack Nomad Services
TeamViewer has issued important security bulletins addressing multiple vulnerabilities across its Digital Employee Experience (DEX) product line (formerly 1E). The updates patch high-severity flaw…
⤷ Title: ChatGPT Atlas Under Guard: OpenAI Fortifies Browser Agent Against “Prompt Injection” Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:27:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adversarial Training #Agent Mode #AI security #Browser Agent #ChatGPT Atlas #Cyber Security #LLM Safety #OpenAI #Prompt injection #red_teaming
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:27:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adversarial Training #Agent Mode #AI security #Browser Agent #ChatGPT Atlas #Cyber Security #LLM Safety #OpenAI #Prompt injection #red_teaming
Daily CyberSecurity
ChatGPT Atlas Under Guard: OpenAI Fortifies Browser Agent Against “Prompt Injection” Attacks
As artificial intelligence begins to browse the web on our behalf, the battleground for security is shifting from servers to our own browser tabs. OpenAI has deployed a critical security update fo…
⤷ Title: The “lc” Leak: Critical 9.3 Severity LangChain Flaw Turns Prompt Injections into Secret Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:22:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Agents #CVE_2025_68664 #data exfiltration #Environment Variables #Information Disclosure #LangChain #LLM Security #Prompt injection #Python Security #Serialization Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:22:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Agents #CVE_2025_68664 #data exfiltration #Environment Variables #Information Disclosure #LangChain #LLM Security #Prompt injection #Python Security #Serialization Injection
Daily CyberSecurity
The “lc” Leak: Critical 9.3 Severity LangChain Flaw Turns Prompt Injections into Secret Theft
A critical vulnerability was found in LangChain, the popular open-source framework used to power Large Language Model (LLM) agents. The flaw, tracked as CVE-2025-68664, carries a severe CVSS score…
⤷ Title: Hackers Weaponize npm to Hunt Critical Infrastructure Sales Teams
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:19:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #adril7123 #AiTM #Critical Infrastructure #evilginx #Interpack #K_Fair #Manufacturing Security #MicroSecure #Microsoft 365 #npm #phishing #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:19:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #adril7123 #AiTM #Critical Infrastructure #evilginx #Interpack #K_Fair #Manufacturing Security #MicroSecure #Microsoft 365 #npm #phishing #Socket #supply chain attack
Daily CyberSecurity
Hackers Weaponize npm to Hunt Critical Infrastructure Sales Teams
A new investigation by The Socket Threat Research Team has uncovered a sophisticated spear-phishing operation that has abused the npm registry for at least five months to target critical infrastru…
⤷ Title: Zimbra Under Siege: High-Severity LFI Vulnerability Exposes Internal Files to Unauthenticated Attackers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:11:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67809 #CVE_2025_68645 #Email Security #hardcoded credentials #infosec #lfi #local file inclusion #Patch Update #ZCS #Zimbra
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:11:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67809 #CVE_2025_68645 #Email Security #hardcoded credentials #infosec #lfi #local file inclusion #Patch Update #ZCS #Zimbra
Daily CyberSecurity
Zimbra Under Siege: High-Severity LFI Vulnerability Exposes Internal Files to Unauthenticated Attackers
Administrators of the popular Zimbra Collaboration Suite (ZCS) are being urged to patch immediately after the discovery of two distinct security vulnerabilities. The most severe of the pair allows…